CVE-2024-49202: High severity keyfactor command vulnerability
Keyfactor Command before 12.5.0 has Incorrect Access Control: access tokens are over permissioned, aka 64099. The fixed versions are 11.5.1.1, 11.5.2.1, 11.5.3.1, 11.5.4.5, 11.5.6.1, 11.6.0, 12.2.0.1, 12.3.0.1, 12.4.0.1, 12.5.0, and 24.4.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49202?
CVE-2024-49202 has been identified as a vulnerability with a critical severity due to incorrect access control allowing over-permissioned access tokens.
How do I fix CVE-2024-49202?
To fix CVE-2024-49202, upgrade Keyfactor Command to versions 11.5.1.1, 11.5.2.1, 11.5.3.1, 11.5.4.5, 11.5.6.1, 11.6.0, 12.2.0.1, 12.3.0.1, 12.4.0.1, 12.5.0, or 24.4.0.
What versions of Keyfactor Command are affected by CVE-2024-49202?
CVE-2024-49202 affects Keyfactor Command versions before 12.5.0.
What type of vulnerability is CVE-2024-49202?
CVE-2024-49202 is classified as an access control vulnerability due to over-permissioned access tokens.
Who is affected by CVE-2024-49202?
Any user or organization utilizing Keyfactor Command versions prior to 12.5.0 is affected by CVE-2024-49202.